AI Model Guide

OpenAI's Agents API and Computer Use in 2026: What It Means for Marketing Automation

OpenAI now runs the agent loop for you, and since 29 September the agent can work in a hosted browser. The capability is the headline. The approval rules are what decide whether it is safe to point at a real account.

Distk Editorial Oct 2026 10 min read

The OpenAI Agents API entered public beta on 10 September 2026, giving applications access to OpenAI's managed Codex harness: OpenAI runs sessions, orchestration, context compaction and recovery while your application supplies tools and chooses an OpenAI-hosted, self-hosted or no sandbox. On 29 September 2026 OpenAI added computer use, so an agent can operate websites in an OpenAI-hosted browser. Every new website origin needs user approval, including public sites, but OpenAI states that origin approval does not enforce confirmation before individual actions, so consequential actions should be kept out of reach rather than gated by the agent asking first. Sign-in supports email, passwords and verification codes but not passkeys or QR codes. You pay model, tool and container rates; there is no separate Agents API fee.

What Is the OpenAI Agents API in 2026?

The Agents API is OpenAI's managed way to run an agent, released in public beta on 10 September 2026. OpenAI describes it as giving "your application access to the Codex harness through an OpenAI-managed API". OpenAI runs the sessions, orchestration, context compaction and recovery; your application supplies the tools and chooses where the agent executes. On 29 September 2026 OpenAI added computer use, so an agent can now work inside an OpenAI-hosted browser.

For a marketing or operations lead the useful translation is this. Until now, building an agent meant building the loop that keeps it going: remembering what it did, recovering when it failed, summarising history when the context filled up. The Agents API takes that loop off your hands. You describe the agent, give it a task, and follow its progress through events or webhooks.

AttributeWhat OpenAI documents in 2026Why it matters to a business team
StatusPublic beta since 10 September 2026; SDK calls sit under client.beta.agentsBeta interfaces can change. Do not build a client deliverable that assumes they will not.
Who runs the loopOpenAI runs a managed Codex harnessLower build effort than writing your own agent loop.
Where work executesOpenAI-hosted sandbox, self-hosted sandbox, or no sandboxA self-hosted sandbox keeps execution on infrastructure you control.
StateDurable sessions with saved configuration, turns and itemsAn agent can pick up yesterday's task without you replaying the history.
Computer useAdded 29 September 2026; runs a browser in an OpenAI-hosted environmentThe agent can operate websites through their interface.
PricingModel usage at the selected model's API rates; hosted sandboxes at standard container ratesThere is no separate Agents API fee, but the sandbox meter runs too.

How Is the Agents API Different From the Agents SDK and the Responses API?

The difference is who runs the agent loop. OpenAI's own comparison puts the Agents API at "Low" integration effort, because OpenAI runs the managed harness and saves progress. The Agents SDK runs inside your application at "Medium" effort and gives you control over deployment, storage and approvals. The Responses API is "High" effort: you call models directly and build the agent yourself.

Agents APIAgents SDKResponses API
OpenAI's stated useLong-running tasks where OpenAI manages the agent and saves its progressBuilding agents with custom tools and workflows in your applicationCalling models directly or building an agent from scratch
Where the agent runsOpenAI runs a managed Codex harnessInside your applicationYour application, with optional hosted orchestration
Integration effortLowMediumHigh
Execution environmentOpenAI hosted sandbox, self-hosted sandbox, or no sandboxYour runtime and sandbox provider integrationsYour own execution environment

OpenAI lists what the managed harness provides: running commands and code in a sandbox, applying skills and instructions, connecting to external data through tools or MCP, steering the agent while it works, summarising previous work to manage the context window, delegating subtasks to subagents, and resuming a session where it left off. Its example applications include an incident response agent, a Slack bot, a read-only SQL data analyst and a document reviewer.

How Does Computer Use Work in the Agents API in 2026?

You enable it with two settings: add { "type": "computer_use" } to the agent's tools, and set the environment to openai_hosted with the desktop enabled. The browser then runs in an OpenAI-hosted environment, and the agent decides what to do next from what it sees on screen. OpenAI frames the uses as testing a website, collecting information, or using an application through its interface.

// From OpenAI's computer use guide: the two settings that enable browser access
agent.tools: [{ "type": "computer_use" }]
environment.type: "openai_hosted"
environment.desktop.enabled: true

Browser activity appears in session output as computer_use_call items, each with a status of in_progress, completed, failed or incomplete. Screenshots are excluded from API output by default; you can turn them on with include_screenshots, and OpenAI warns they "can contain sensitive page or account data" and should be kept out of logs.

Why Do the Approval Rules Matter More Than the Capability?

Because they decide what the agent can do without a person, and the documentation is precise about the limits. The browser "requires the user's approval before accessing each new website origin, including public websites", and enabling network access does not approve those requests. That is a stronger default than most teams would set themselves.

The sentence to read twice is OpenAI's own heading: "Origin approval does not enforce confirmation before individual actions." Approving a website lets the agent act on that website. If your application must guarantee confirmation before purchases, destructive changes or other consequential actions, OpenAI's guidance is to "restrict the hosted browser to resources that cannot perform them, or use a browser runtime you control". It adds that asking for confirmation through a function tool "relies on the agent calling that function", and that website content should be treated as untrusted.

The design rule this implies for 2026

Approving an origin is approving everything the agent might do there. If a site in scope has a "buy", "delete" or "send" button, the safe architecture is to keep that capability away from the agent entirely, not to ask the agent to check in first. OpenAI says this plainly; most agent demos do not.

How sign-in works

Your application handles sign-in, so credentials never pass through the conversation. Submitted sign-in values "stay outside the agent's model input and are omitted from authentication response items in session history". Three limits are documented:

What Does It Cost to Run an Agent in 2026?

OpenAI documents three meters. Model usage is billed at the selected model's API rates, OpenAI tools at their standard rates, and OpenAI-hosted sandboxes at standard container rates. The pricing page lists containers at "1 GB $0.03, 4 GB $0.12, 16 GB $0.48, 64 GB $1.92 per 20-minute session per container", with web search at 10 US dollars per 1,000 calls plus search content tokens at model rates.

The model choice dominates. Running the same agent on GPT-6 Luna at 0.10 US dollars per million input tokens is a very different budget from running it on GPT-6 Astra at 10 US dollars. OpenAI's own example sessions use gpt-6-astra; that is a demonstration choice, not a requirement.

How Should Marketing and Operations Teams Use the Agents API in 2026?

Treat it as the build option when you need an agent embedded in your own product or workflow, rather than a person working in ChatGPT. For a team that only wants a capable assistant, OpenAI dots and ChatGPT Work are the no-build routes. The Agents API is for when the agent is part of something you ship or run for clients.

WorkflowFit in 2026Control to set
Reading public competitor pages into a weekly briefStrong. Read-only browsing of public origins.Approve only the origins in scope.
QA of your own landing pages and formsStrong. OpenAI names website testing as a use.Point it at staging, not production.
Answering internal questions from a warehouseGood. OpenAI's data analyst example uses read-only SQL.Read-only credentials, always.
Logging into a client's ad account to change budgetsPoor without a controlled runtime.Origin approval does not confirm individual actions.
Anything behind passkey or QR loginNot supported by the sign-in flow.Use an API integration instead.

What Are the Common Mistakes With the Agents API in 2026?

Key Takeaways for 2026

Distk helps growth teams across India and internationally decide where an agent belongs in a workflow, which origins and actions it should never touch, and which model tier keeps it affordable to run every day. If you are scoping an agent build in 2026, that boundary-setting is where we start.

Sources

OpenAI Agents API in 2026: FAQs

What is the OpenAI Agents API in 2026?

A managed way to run agents, released in public beta on 10 September 2026. OpenAI runs the Codex harness, sessions, orchestration, context compaction and recovery, while your application supplies tools and chooses an OpenAI-hosted, self-hosted or no sandbox.

What did OpenAI add to the Agents API on 29 September 2026?

Computer use. Agents can complete tasks in an OpenAI-hosted browser, with website access approvals and sign-in handled by your application. You enable it by adding the computer_use tool and an openai_hosted environment with the desktop enabled.

Does approving a website let the agent do anything on it?

Effectively yes. OpenAI states that origin approval does not enforce confirmation before individual actions. If you need confirmation before purchases or destructive changes, restrict the browser to resources that cannot perform them, or use a browser runtime you control.

Which sign-in methods does Agents API computer use support?

Email addresses, passwords and verification codes. Passkeys and QR-code sign-in are not supported, and only the main agent can request browser authentication, not subagents. Authentication requests expire after five minutes.

How much does the OpenAI Agents API cost?

There is no separate Agents API fee. Model usage is billed at the selected model's API rates, OpenAI tools at their standard rates, and OpenAI-hosted sandboxes at container rates of 0.03 to 1.92 US dollars per 20-minute session depending on size.

Should a marketing team use the Agents API or ChatGPT Work?

ChatGPT Work and dots are the no-build routes for people working in ChatGPT. The Agents API is for agents embedded in your own product or a client workflow, where you need to control tools, approvals and where the agent runs.

Decide what the agent must never touch

Distk helps growth teams scope agents: which websites and actions are in reach, which credentials stay outside the sandbox, and which model tier keeps the agent affordable to run every day.

Start the conversation →